<feed xmlns='http://www.w3.org/2005/Atom'>
<title>archsetup/assets/wireguard-config/README.org, branch main</title>
<subtitle>Builds a full dev workstation from a bare Arch Linux install.
</subtitle>
<id>https://git.cjennings.net/archsetup/atom?h=main</id>
<link rel='self' href='https://git.cjennings.net/archsetup/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/'/>
<updated>2026-07-20T13:18:38+00:00</updated>
<entry>
<title>docs: close WireGuard leak task, note cgit follow-up</title>
<updated>2026-07-20T13:18:38+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-07-20T13:18:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=18429ed05b1653c17f2d3e8257b1297799162c48'/>
<id>urn:sha1:18429ed05b1653c17f2d3e8257b1297799162c48</id>
<content type='text'>
Record the resolution (keys expired, all 10 configs purged from history, server
gc'd, verified via anonymous clone) and file the cgit-exposure audit as the
systemic follow-up. Update the config README to the out-of-band workflow.
</content>
</entry>
<entry>
<title>fix(security): stop tracking plaintext WireGuard configs</title>
<updated>2026-07-20T13:05:34+00:00</updated>
<author>
<name>Craig Jennings</name>
<email>c@cjennings.net</email>
</author>
<published>2026-07-20T13:05:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.cjennings.net/archsetup/commit/?id=a20e8c2f839fa53659f2fc3eba18645e541e753e'/>
<id>urn:sha1:a20e8c2f839fa53659f2fc3eba18645e541e753e</id>
<content type='text'>
The repo is public via cgit, so the three plaintext configs (added 849c3fa)
exposed live Proton PrivateKeys. Remove them, gitignore plaintext, and document
the encrypted-only workflow. Keys rotated at Proton; history purged separately.
</content>
</entry>
</feed>
